SASE / Zero Trust
Gateway review
Score: 6/10Easy DNS filtering; the full agent rollout is a bigger commitment.
The breakdown explains the score. It is not an average. How to read these.
Last updated
Gateway’s DNS filtering is easy to deploy. Point resolvers at Cloudflare and you get category blocking, malware protection, and logging. For a small team, an afternoon’s work produces a worthwhile security improvement.
HTTP inspection, TLS decryption, and egress policies are a much bigger commitment. They require the WARP client on every device and a trusted root certificate. Certificate pinning, platform-specific client quirks, and user friction all become your problem.
It is a capable product in a crowded SASE market. From a smaller organization’s perspective, the easy parts are great and the deeper features demand more investment than most teams want to make.
Status page incidents
Published under Gateway, plus incidents whose title names it.
- Last 3 years
- 50
- 14 from the title
- Major or critical
- 6
- Median time open
- 1.1 h
- Since January 2023
- 99
Counts what Cloudflare published, not what broke: time open is how long the status entry stayed open, and nothing before January 2023 is tracked at all. Incidents Cloudflare tagged against nothing but named in the title are counted too. The caveats in full.